First published: Mon Mar 21 2022(Updated: )
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Gogs Gogs | <0.12.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0415 is a vulnerability that allows remote command execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
The severity of CVE-2022-0415 is critical with a severity value of 8.8.
CVE-2022-0415 affects Gogs software prior to version 0.12.6 and allows remote command execution in uploading repository files.
To fix CVE-2022-0415, update Gogs software to version 0.12.6 or later.
You can find more information about CVE-2022-0415 at the following references: [Github Commit](https://github.com/gogs/gogs/commit/0fef3c9082269e9a4e817274942a5d7c50617284) and [Huntr Bounty](https://huntr.dev/bounties/b4928cfe-4110-462f-a180-6d5673797902).